The Cyber Academy take
ISO 31000 is the generic risk-management standard. Principles plus framework plus iterative process. NOT a certifiable management system, there is no ISO 31000 Lead Auditor, despite what some catalogues claim. The PECB path is Foundation → Risk Manager → Lead Risk Manager. Use it when risk is broader than information security alone.
A generic standard, not a management system
ISO 31000 is the international reference for managing risk of any kind, in any organisation. It is deliberately generic. The same principles, framework and process apply whether the risk in question is financial, operational, strategic, safety, environmental or cyber. That breadth is the point. A purchasing decision, a new market entry and a ransomware exposure can all be assessed with the same vocabulary and the same logic, which lets a board compare risks that would otherwise sit in separate silos with incompatible scoring.
The most common misunderstanding is treating ISO 31000 like ISO 27001 or ISO 22301. It is not a requirements standard and it is not certifiable. There is no ISO 31000 management system to audit and no ISO 31000 Lead Auditor qualification, whatever some training catalogues advertise. The standard offers guidance to be adapted, not clauses to be conformed to. Organisations integrate it into how they already run, rather than bolting on a separate certified system.
Principles, framework and process
ISO 31000 is built on three connected parts that practitioners learn to keep distinct. The principles state what good risk management looks like: it is integrated into the organisation, structured, tailored to context, inclusive of stakeholders, dynamic, based on the best available information and oriented toward creating and protecting value. The framework is about leadership and governance, how risk management is mandated, designed, implemented, evaluated and improved over time so it actually sticks. The process is the operational engine people run repeatedly.
- Establishing the context. Defining scope, objectives and the internal and external environment the risk lives in.
- Risk identification, analysis and evaluation, together forming the risk assessment.
- Risk treatment. Choosing how to modify the risk, then implementing and verifying the controls.
- Communication, consultation, monitoring and review, which wrap the whole cycle and keep it current.
How it relates to neighbouring standards
ISO 31000 is the parent. ISO 27005 applies the same process logic to information security risk and aligns with an ISO 27001 information security management system. EBIOS Risk Manager, the French method published by ANSSI, is a concrete, scenario-driven way to run a security risk assessment that maps onto the same stages. None of these contradict ISO 31000; they specialise it. A risk manager who understands the generic process can move between them without relearning the fundamentals, which is why the standard is taught first.
Vocabulary is shared through ISO Guide 73, the companion that defines risk-management terms so that "likelihood", "consequence" and "risk treatment" mean the same thing across documents and teams. Aligning on those definitions early prevents the scoring arguments that derail many risk workshops.
What practitioners actually do with it
In practice ISO 31000 shapes the risk register, the assessment workshops and the reporting line to leadership. A risk manager uses it to justify why a risk is owned, scored and treated the way it is, and to show that the approach is consistent rather than improvised case by case. Because the standard is not certifiable, the recognised way to demonstrate competence is through a personal credential. The PECB pathway runs Foundation, then Risk Manager, then Lead Risk Manager, building from awareness of the concepts to leading a risk-management programme across an organisation.
Frequently asked questions
01Can you get certified to ISO 31000?
No. ISO 31000 is guidance, not a requirements standard, so there is no organisational certification against it. You demonstrate competence through personal credentials such as the PECB Risk Manager or Lead Risk Manager certifications, not an audited management system.
02Is there an ISO 31000 Lead Auditor qualification?
No, despite some catalogues listing one. Lead Auditor schemes exist for certifiable management system standards like ISO 27001. ISO 31000 is not certifiable, so the recognised progression is Foundation, then Risk Manager, then Lead Risk Manager.
03What is the difference between ISO 31000 and ISO 27005?
ISO 31000 is the generic, enterprise-wide risk-management standard covering any risk type. ISO 27005 applies the same process specifically to information security risk and aligns with an ISO 27001 management system. ISO 27005 specialises ISO 31000 rather than competing with it.
04When should an organisation use ISO 31000 rather than a security-specific method?
Use ISO 31000 when risk is broader than information security, for example enterprise, strategic, financial or operational risk that needs one shared framework. For information security risk specifically, layer ISO 27005 or EBIOS Risk Manager underneath it.
05What are the three main components of ISO 31000?
The principles, which describe what effective risk management looks like; the framework, which governs how risk management is led and embedded; and the process, the iterative cycle of context, assessment, treatment, and ongoing communication and review.